CVE-2019-9918: Harmistechnology Je Messenger
Critical severity, CVSS 9.1. EPSS: 1.3% chance of exploitation in the next 30 days.
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Statements can be executed in the database.
Affected products
- Harmistechnology Je Messenger: version 1.2.2 only
Published 2019-03-29. Last modified 2026-06-17.